SENTINEL · AUTONOMOUS APPSEC AGENT

Scan report · proven, not asserted

Target targets/vulnerable_app Model illustrative fixture (no model call, not a scan result) Runtime 12.34s Generated 2026-09-26 15:17 UTC
5
Candidates
1
Line proven
2
Class only
1
Not testable
1
No path
1
Files fixed
1 critical

Line-proven 1

The exploit succeeded and the reported line executed while it ran. These are claims demonstrated about this code.

critical

SQL Injection

LINE PROVEN
app.py:33 conf 95%

username from request flows unsanitized into an SQL string.

Execution witnessreached app.py:33 during the exploit.
Proof-of-concept exploit · 1 attempt(s)
import app
# ... exploit ...
print('SENTINEL_PWNED')
Sandbox output
SENTINEL_PWNED
Proposed secure-fix diff not verified
--- a/app.py
+++ b/app.py
@@ -33 +33 @@
-    query = "SELECT * FROM users WHERE name = '" + username + "'"
+    cursor.execute("SELECT * FROM users WHERE name = ?", (username,))

Class-only 2

An exploit printed the success marker, but the trace shows the reported line never executed. That proves the vulnerability class is exploitable, not that this line is — so these are held back from the headline count and are not patched.

high

Hardcoded Secret

CLASS ONLY
app.py:18 conf 90%

an admin password is written directly in source.

Execution witnessonly imported app.py — line 18 ran at import time, which is not counted as reaching it. Only the vulnerability class was demonstrated.
Proof-of-concept exploit · 1 attempt(s)
import app
print('SENTINEL_PWNED')
Sandbox output
SENTINEL_PWNED
high

Insecure Deserialization

CLASS ONLY
app.py:61 conf 70%

pickle.loads on attacker-supplied bytes.

Execution witnessnever executed any code in app.py — the exploit reproduced the class in isolation.
Proof-of-concept exploit · 1 attempt(s)
import sqlite3
# reproduces the class in isolation
print('SENTINEL_PWNED')
Sandbox output
SENTINEL_PWNED

Not testable 1

The exploit could not run because the sandbox image is missing a third-party package the target imports. Nothing was proven or disproven — these are reported separately rather than counted as failed exploits, because calling them unproven would claim a test that never happened.

critical

Command Injection

NOT TESTABLE
app.py:45 conf 100%

host from the request is appended to a shell command passed to os.system.

Sandbox gapThe target imports flask, which is not installed in the sandbox image. The exploit stopped at that import, so this claim was never tested.
Proof-of-concept exploit · 3 attempt(s)
import app
# ... exploit ...
print('SENTINEL_PWNED')
Sandbox output
ModuleNotFoundError: No module named 'flask'

Not demonstrated 1

Flagged by the hunter, then either rejected by the static reachability gate before any model call (1) or never demonstrated by a working exploit. They are shown so nothing is silently dropped.

high

Command Injection

NO PATH
app.py:50 conf 40%

host reaches subprocess.run with an argument list (no shell).

Static gate`subprocess.run` at line 50: argument vector passed without a shell (shell=False)